← Back to news

CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited

The Hacker News08/01/2026, 04:52
Read full article →

Summary

AI-Generated

Key Points:

  • CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting Microsoft Office and HPE OneView.
  • The vulnerabilities include CVE-2025-37164, which impacts all versions of HPE OneView prior to version 11.00. The risk is heightened by the public availability of a proof-of-concept exploit.
  • Organizations are strongly advised to apply available hotfixes for affected versions of OneView and ensure updates are completed by January 28, 2026, to mitigate risks.

Technical Details: CVE-2025-37164 affects all versions of HPE OneView prior to 11.00, with active exploitation reported. The vulnerability's details were disclosed last month, and a proof-of-concept exploit was released on December 23, 2025.

MITRE ATT&CK Techniques: None mentioned

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.